CVE-2026-82652

Summary

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking content unlisted.

Affected Software

VendorProductVersion RangeStatus
siyuan-notesiyuan0 < 3.8.1affected
siyuan-notesiyuan3.8.1unaffected

Weaknesses

  • CWE-668: Exposure of Resource to Wrong Sphere

References